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IN THE CLAIMS 

Amended claims follow: 
1-6. (Cancelled) 

1. (Currently Amended) A computer program product for controlling a computer 
to detect malware, said computer program product comprising; 

file access request receiving logic operable to receive at an assessment computer a 
file access clearance request from a requesting computer, said file access clearance 
request including data identifying a computer file to be accessed by said requesting 
computer; 

file access clearance response generating logic operable in dependence upon said 
data identifying said computer file to determine if said computer file has previously been 
assessed as not containing malware and to generate a file access clearance response; and 

file access clearance response transmitting logic operable to transmit said file 
access clearance response to said requesting computer; 

wherein said assessment computer stores a database of computer files and said 
database includes for each computer file a persistence flag indicating whether an entry 
relating to said computer file should be purged fi-om said database during purge 
operationsi 

wherein said database includes for each computer file fields specifying a filename 
of said computer file, data identifyijqg said requesting computer and a storage location of 
said computer file, and a checksum value calculated from said computer file , 

8. (Currently Amended) A computer program product as claimed in claim 7, 
wherein said data identifying said computer file includes [[a] ]said checksum value 
calculated from said computer file. 

9. (Currently Amended) A computer program product as claimed in claim 7, 
wherein said data identifying said computer file includes One or more of [[a]]said 
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filename of said computer file, said data identifymg said requesting computer and 
[[a]]sMd storage location of said computer file. 

10. (Original) A computer program product as claimed in claim 7, wherein if said 
file access clearance response indicates a scan of said computer file is required by said 
assessment computer, then computer file receiving logic is operable to receive at said 
assessment computer said computer file from said requesting computer and performing a 
malware scan of said computer file. 

1 1 . (Original) A computet program product as claimed in claim 7, wherein if said 
file access clearance response indicates access to said computer file is denied, then 
triggering a denied access response in said assessment computer. 

12. (Previously Presented) A computer program product as claimed in claim 7, 
wherein said database of computer files specifies whetiier respective computer files 
contain malware. 

13. (Currently Amended) A computer program product as claimed in claim 12, 
wherein said database further i ncludes for each computer file another fi eld[[s]] specifying 

or mor e of a filonam e of said computer file, data - id e ntifying said roquogting 
computor and a storago location of said oomputor file, a ohoclcGum value colcu l atod from 
said computer file and an access flag indicating whether access to said computer file is 
denied. 

14. (Original) A computer program product as claimed in claim 7, wherein said 
assessment computer is operable in at least a higher level security mode and a lower level 
security mode, said assessment computer serving to deny access to greater range of 
computer files when operating in said higher level security mode compared with said 
lower level security mode. 
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15. (Original) A computer program product as claimed in claim 14, wherein said 
assessment computer is triggered to change ftom said lower level security mode to said 
higher level security mode by a lock down trigger message received at said assessment 
computer from a remote computer. 

16. (Original) A computer program product as claimed in claim 7, wherein a 
plurality of requesting computers share access to an assessment computer for determining 
whether file access requests by those requesting computers should be denied. 

17. (Currently Amended) A computer program product for controlling a computer 
to detect malware, said computer program product comprising: 

file access request detecting logic operable to detect a file access request to a 
computer file by a requesting computer; 

file access clearance request generating logic operable to generate a file access 
clearance request including data identifymg said computer file; 

file access clearance request transmitting logic operable to transmit said file 
access clearance request from said requesting computer to an assessment computer 
responsible for assessment of whether said computer file contains malware; 

file access clearance request receiving logic operable to receive at said assessment 
computer said file access clearance request firom a requesting computer; 

file access clearance response generating logic operable in dependence upon said 
data identifying said computer file to determine if said computer file has previously been 
assessed as not containing malware and to generate a file access clearance response; 

file access clearance response transmitting logic operable to transmit said file 
access clearance response to said requesting computer; 

file access clearance response receiving logic operable to receive at said 
requesting computer said file access clearance response from said assessment computer; 
and 

file access permitting logic operable if said file access clearance response 
indicates said computer file does not contain malware to permit said file access request 
by said requesting computer; 
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A^erein said assessment computer stores a database of computer files and said 
database includes for each computer file a persistence flag indicating whether an entry 
relating to said computer file should be purged firom said database during purge 
operations; 

wherein said database includes for each computer file fields specifying a filename 
of said computer file, data identifying said requesting computer and a storage location of 
said computer file, and a checksum value calculated from said computer file . 

18. (Currently Amended) A computer program product as claimed in claim 17, 
wherein said data identifying said computer file includes [(a)]sMd checksum value 
calculated from said computer file. 

1 9. (Currently Amended) A computer program product as claimed in claim 1 7, 
wherein said data identifying said computer file includes one or more of Ff all said 
filename of said computer file, said d ata identifying said requesting computer and 
[[a]] said storage location of said computer file. 

20. (Original) A computer program product as claimed in claim 17, wherein if 
said file access clearance response indicates a scan of said computer file is required by 
said assessment computer, then computer file transmitting logic is opemble to transmit 
said computer file from said requesting computer to said assessment computer, receiving 
at said assessment computer said computer file from said requesting computer and 
performing a malware scan of said computer file, 

21. (Original) A computer program product as claimed in claim 17, wherein if 
said file access clearance response indicates access to said computer file is denied, then 
triggering a denied access response in said assessment computer. 

22. (Original) A computer program product as claimed in claim 17, wherein if 
said file access clearance response indicates access to said computer file is denied, then 
triggering a denied access response in said requesting computer. 
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23. (Previously Presented) A computer program product as claimed in claim 17, 
wherein said database of computer files specifies whether respective computer files 
contain nmlware, 

24. (Currently Amended) A computer program product as claimed in claim 23, 
wherein said database farther i ncludes for each computer file another fi cldrrsll specifying 
on e or mor e of ot fil e nam e- Q - f^d - Gomputcr - file, data id e ntifying said r e quoDting 
oomputor and q Qtoragc-location of said comput e r file> a chookinim valu e calculat e d firom 
said - oomputer fil e and an access flag indicating whether access to said computer file is 
denied. 

25. (Original) A computer program product as claimed in claim 17, wherein said 
assessment computer is operable in at least a higher level security mode and a lower level 
security mode, said assessment computer serving to deny access to greater range of 
computer files when operating in said higher level security mode compared with said 
lower level security mode. 

26. (Original) A computer program product as claimed in claim 25, wherein said 
assessment computer is triggered to change from said lower level security mode to said 
higher level security mode by a lock down trigger message received at said assessment 
computer from a remote computer. 

27. (Previously Presented) A computer program product as claimed in claim 17, 
wherein a plurality of requesting computers share access to an assessment computer for 
determining whether file access requests by those requesting computers should be denied. 

28-33. (Cancelled) 

34, (Currently Amended) A method of detecting malware, said method 
comprising the steps ofi 
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receiving at an assessment compoiter a file access clearance request from a 
requesting computer, said file access clearance request including data identifying a 
computer file to be accessed by said requesting computer, 

in dependence upon said data identifying said computer file determining if said 
computer file has previously been assessed as not containing malware and generating a 
file access clearance response; and 

transmitting said file access clearance response to said requesting compxiter; 

wherein said assessment computer stores a database of computer files and said 
database includes for each computer file a persistence flag indicating whether an entry 
relating to said computer file should be purged from said database during purge 
operations! 

wherein said database includes for each computer file fields specifying a filename 
of said computer file> data identifying said requesting computer and a storage location of 
said computer file, and a checksum value calculated from said computer file . 

35. (Currently Amended) A method as claimed in claim 34, wherein said data 
identifying said computer file includes [[a]] said checksum value calculated from said 
computer file. 

36. (Currently Amended) A method as claimed in claim 34, wherein said data 
identifying said computer file includes one or more of [[a]]said filename of said computer 
file, said d ata identifying said requesting computer and [[a]]said storage location of said 
computer file. 

37. (Previously Presented) A method as claimed in claim 34, wherein if said fUe 
access clearance response indicates a scan of said computer file is required by said 
assessment computer, then receiving at said assessment computer said computer file from 
said requesting computer and performing a malware scan of said computer file. 
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38. (Previously Presented) A method as claimed in claim 34, wherein if said file 
access clearance response indicates access to said computer file is denied, then triBgering 
a denied access response in said assessment computer, 

39. (Previously Presented) A method as claimed in claim 34, v^herein said 
database of computer files specifies whether respective computer files contain malware. 

40. (Cunently Amended) A method as claimed in claim 39, wherein said database 
further i ncludes for each computer file ^a&eLfield[[s]] specifying e ac - ormor e of a 
fi lename of s aid computor file, data identifying said roquosting computer and a storage 
location of said computer fil e , a choctoum value ■ calculat e d firom said oomputei fil e and 
an access flag indicating whether access to said computer file is denied. 

41. (Previously Presented) A method as claimed in claim 34, wherein said 
assessment computer is operable in at least a higher level security mode and a lower level 
security mode, said assessment computer serving to deny access to greater range of 
computer files when operating in said higher level security mode compared with said 
lower level security mode. 

42. (Previously Presented) A method as clahned in claim 41 > wherein said 
assessment computer is triggered to change from said lower level security mode to said 
higher level security mode by a lock down trigger message received at said assessment 
computer fi^m a remote computer. 

43. (Previously Presented) A method as claimed in claim 34, wherein a plxjrality 
of reqxiesting computers share access to an assessment computer for determining whether 
fde access requests by those requesting computers should be denied, 

44. (Currently Amended) A method of detecting malware, said method 
comprising the steps of; 

detecting a file access request to a computer file by a requesting computer; 
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generating a file access clearance request including data identifying said computer 

file; 

transmitting said file access clearance request from said requesting computer to an 
assessment computer responsible for assessment of whether said computer file contains 
malwarc; 

receiving at said assessment computer said file access clearance request from a 
requesting computer; 

in dependence upon said data identifying said computer file determining if said 
computer file has previously been assessed as not containing malware and generating a 
file access clearance response ■ 

transmitting said file access clearance response to said requesting computer; 

receiving at said requesting computer said file access clearance response from 
said assessment computer; and 

if said file access clearance response indicates said computer file does not contain 
malware, then permitting said file access request by said requesting computer; 

wherein said assessment computer stores a database of computer files and said 
database includes for each computer file a persistence flag indicating whether an entry 
relating to said computer file should be purged from said database during purge 
operations^ 

wherein said database includes for each computer file fields specifidn g a filename 
of said computer file, data identifvdnE said requesting computer an d a storage location of 
said computer file, and a checksum value calculated from said computer file . 

45. (Currently Amended) A method as claimed in claim 44, wherein said data 
identifying said computer file includes [[a]]said checksum value calculated from said 
computer file, 

46. (Currently Amended) A method as claimed in claim 44, wherein said data 
identifying said computer file includes one or more of [[a]]s^ filename of said computer 
file, said data identifying said requesting computer and [[a]]smd storage location of said 
computer file, 
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47. (Previously Presented) A method as claimed in claim 44, wherein if said file 
access clearance response indicates a scan of said computer file is required by said 
assessment computer, then transmitting said computer file fixjm said requesting computer 
to said assessment computer, receiving at said assessment computer said computer file 
from said requesting computer and performing a malware scan of said computer file. 

48. (Previously Presented) A method as claimed in claim 44, wherein if said file 
access clearance response indicates access to said computer file is denied, then triggering 
a denied access response in said assessment computer. 

49. (Previously Presented) A method as claimed in claim 44, wherein if said file 
access clearance response indicates access to said computer file is denied, then triggering 
a denied access response in said requesting computer. 

50. (Previously Presented) A method as claimed in claim 44, wherein said 
database of computer files specifies whether respective computer files contain malware. 

51. (Currently Amended) A method as claimed in claim 50^ wherein said database 
further includes for each computer file another fi eld[[sn specifying one or more of a 
filenam e of said comput e r filo, data idoat i i y mg^aid r e questing computer ond r a storage 
location o^aid - oomput e r fil e , a ch e clcsum valu e caloulalod from said comput e r fil e and 
an access flag indicating whether access to said computer file is denied. 

52. (Previously Presented) A method as claimed in claim 44, wherein said 
assessment computer is operable in at least a higher level secxmty mode and a lower level 
security mode, said assessment computer serving to deny access to greater range of 
computer files when operating in said higher level security mode compared with said 
lower level security mode. 
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53. (Previously Presented) A method as claimed in claim 52, wherein said 
assessment computer is triggered to change from said lower level secxirity mode to said 
higher level security mode by a look down trigger message received at said assessment 
computer from a remote computer. 

54. (Previously Presented) A method as claimed in claim 44, wherein a plurality 
of requesting computers share access to an assessment computer for determining whether 
file access requests by those requesting computers should be denied 

55-60- (Cancelled) 

61. (Currently Amended) Apparatus for controlling a computer to detect tnalware, 
said apparatus comprising; 

a file access request receiver operable to receive at an assessment computer a file 
access clearance request from a requesting computer, said file access clearance request 
including data identifying a computer file to be accessed by said requesting computer; 

a file access clearance response generator operable in dependence xipon said data 
identifying said computer file to determine if said computer file has previously been 
assessed as not containing malware and to generate a file access clearance response; and 

a file access clearance response transmitter operable to transmit said file access 
clearance response to said requesting computer; 

wherein said assessment computer stores a database of computer files and said 
database includes for each computer file a persistence flag indicating whether an entry 
relating to said computer file should be purged from said database during purge 
operations; 

wherein said database includes for each computer file fields specifying a filename 
of said computer file, data identifving said requesting computer and a storage location of 
said computer file, and a checksxun value calculated from said computer file . 
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62. (Currently Amended) Apparatus as claimed in claim 61, wherein said data 
identifying said computer file includes [[a]] said checksum value calculated jfrora said 
computer file. 

63. (Currently Amended) Apparatus as claimed in claim 61, wherein said data 
identifying said computer file includes one or more of [[ajjsaid filename of said computer 
file, said d ata identifying said requesting computer and [[a]]said storage location of said 
computer file. 

64. (Previously Presented) Apparatus as claimed in claim 61 ^ wherein if said file 
access clearance response indicates a scan of said computer file is required by said 
assessment cornputer, then a computer file receiver is operable to receive at s^d 
assessment computer said computer file from said requesting computer and performing a 
malware scan of said computer file. 

65- (Previously Presented) Apparatus as claimed in claim 61, wherein if said file 
access clearance response indicates access to said computer file is denied, then triggering 
a denied access response in said assessment computer. 

66. (Previously Presented) Apparatus as claimed in claim 61 , wherein said 
database of computer files specifies whether respective computer files contain malware. 

67. (Currently Amended) Apparatus as claimed in claim 66, wherein said 
database further i ncludes for each computer file another fieldr[s1] specifyin g one or more 
of a filenam e of said comput e r fil e , data id e ntifying said r e qu e £?tine comput e r and a 
storoge location - of aaid - Qomputcr - filo r O ohcokoum vqIuq ooloulatcd from oaid eomputo f 
fil e and an access flag indicating whether access to said computer file is denied. 

68. (Previously Presented) Apparatus as claimed in claim 61, wherein said 
assessment computer is operable in at least a higher level security mode and a lower level 
security mode, said assessment computer serving to deny access to greater range of 
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computer files when operating in said higher level security mode compared with said 
lower level security mode. 

69. (Previously Presented) Apparatus as claimed in claim 68, wherein said 
assessment computer is triggered to change from said lower level security mode to said 
higher level security mode by a lock down trigger message received at said assessment 
computer from a remote computer. 

70. (Previously Presented) Apparatus as claimed in claim 61, wherein a plurality 
of requesting computers share access to an assessment computer for determining whether 
file access requests by those requesting computers should be denied, 

71 . (Currently Amended) Apparatus for controlling a computer to detect malware, 
said apparatus comprising; 

a file access request detector operable to detect a file access request to a computer 
file by a requesting computer; 

a file access clearance request generator operable to generate a file access 
clearance request including data identifying said computer file; 

a file access clearance request transmitter operable to transmit said file access 
clearance request from said requesting computer to an assessment computer responsible 
for assessment of whether said computer file contains malware; 

a file access clearance request receiver operable to receive at said assessment 
computer said file access clearance request from a requesting computer; 

a file access clearance response generator operable in dependence upon said data 
identifying said computer file to determine if said computer file has previously been 
assessed as not containing malware and to generate a file access clearance response; 

a file access clearance response transmitter operable to transmit said file access 
clearance response to said requesting computer; 

a file access clearance response receiver operable to receive at said requesting 
computer said file access clearance response from said assessment computer; and 
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a file access permission unit op^able if said file access clearance response 
indicates said computer file does not contain malware to permit said file access request 
by said requesting computer- 

wherein said assessment computer stores a database of computer files and said 
database includes for each computer file a persistence flag indicating whether an entry 
relating to said computer file should be purged from said database during purge 
operations^ 

wherein said database includes for each computer file fields specifying a filename 
of said computer file, data idcntifiing said requesting computer and a storage location of 
said computer file, and a checksum value calculated from said computer file . 

72. (Currently Amended) Apparatus as claimed in claim 71, wherein said data 
identiiying said computer file includes rfal lsaid checksum value calculated from said 
computer file. 

73. (Currently Amended) Apparatus as claimed in claim 71, wherein said data 
identifying said computer file includes one or more of [[a] ] said filename of said computer 
file, sdidata identifying said requesting computer and [[a]]said storage location of said 
computer file. 

74. (Previously Presented) Apparatus as claimed in claim 71 , wherein if said file 
access clearance response indicates a scan of said computer file is required by said 
assessment computer, then a computer file transmitter is operable to transmit said 
computer file from said requesting computer to said assessment computer, receiving at 
said assessment computer said computer file from said requesting computer and 
performing a malware scan of said computer file. 

75. (Previously Presented) Apparatus as claimed in claim 71-, wherein if said file 
access clearance response indicates access to said computer file is denied, then triggering 
a denied access response in said assessment computer. 
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76, (Previously Presented) Apparatus as claimed in claim 71, wherein if said file 
access clearance response indicates access to said computer file is denied, then triggering 
a denied access response in said requesting computer. 

77, (Previously Presented) Apparatus as claimed in claim 71, wherein said 
database of computer files specifies whether respective computer files contain malware. 

78, (Currently Amended) Apparatus as claimed in claim 77, wherein said 
database further includes for each computer file another field[[s]] specifying on e or mor e 
trf - a - filcnomo - of - SQid - oomputor - filerdata idcntij^ing said - requ e sting comput e r and a 
storag e location of said comput e r fil e ^ a ch e cksum voluo caloulatod fi-om ooid computer 
file and an access flag indicating whether access to said computer file is denied. 

79, (Previously Presented) Apparatus as claimed in claim 71, wherein said 
assessment computer is operable in at least a higher level security mode and a lower level 
security mode, said assessment computer serving to deny access to greater range of 
computer files when operating in said higher level security mode compared with said 
lower level security mode, 

80, (Previously Presented) Apparatus as claimed in claim 79, wherein said 
assessment computer is triggered to change fi:om said lower level security mode to said 
higher level security mode by a lock down trigger message received at said assessment 
computer from a remote computer. 

8L (Previously Presented) Apparatus as claimed in claim 71, wherein a plurality 
of requesting computers share access to an assessment computer for determining whether 
file access requests by those requesting computers should be denied 

82. (Cancelled) 
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